A full-cycle detection engineering project demonstrating the complete SOC workflow: log ingestion, Sigma rule development, alert triage, MITRE ATT&CK mapping, rule tuning, and incident response documentation.
detection-engineering-lab/
├── detections/ # Sigma rules (8 rules, 12 ATT&CK techniques)
├── investigations/ # Documented alert triage investigations (5 cases)
├── playbooks/ # Incident response playbook + workflow
├── dashboards/ # Kibana dashboard exports (JSON)
├── logs/ # Sample log sources and field mappings
└── README.md
Stack: Elasticsearch, Kibana, Logstash, Winlogbeat, Elastic Agent
Log sources: Windows Event Logs (Security, System, Sysmon, PowerShell), firewall logs
Detection format: Sigma (compatible with Splunk, Sentinel, QRadar, Elastic Security)
| # | Rule | ATT&CK Technique | Severity | Tuned |
|---|---|---|---|---|
| 1 | Suspicious PowerShell Encoded Command | T1059.001 | High | Yes |
| 2 | Kerberoasting Activity Detected | T1558.003 | High | Yes |
| 3 | LSASS Memory Dump via Task Manager | T1003.001 | Critical | Yes |
| 4 | Remote Desktop Protocol (RDP) from Public IP | T1021.001 | Medium | Yes |
| 5 | Scheduled Task Creation for Persistence | T1053.005 | High | Yes |
| 6 | WMI Process Execution for Lateral Movement | T1047 | High | Yes |
| 7 | Credential Dumping via ProcDump or Mimikatz | T1003.001 | Critical | Yes |
| 8 | Exfiltration Over DNS (Tunneling Detection) | T1048.003 | Medium | Yes |
| 9 | Service Execution for Privilege Escalation | T1543.003 | High | Yes |
| 10 | Account Discovery via net.exe Commands | T1087.001 | Low | Tuned (reduced FP) |
Each investigation follows a structured triage format: alert trigger, initial analysis, evidence collection, MITRE ATT&CK mapping, timeline reconstruction, conclusion, and lessons learned.
| # | Case | ATT&CK Techniques | Verdict |
|---|---|---|---|
| 1 | PowerShell Download Cradle Detected | T1059.001, T1105 | True Positive |
| 2 | Unusual RDP Connection After Hours | T1021.001, T1078 | True Positive |
| 3 | Scheduled Task Named "WindowsUpdate" | T1053.005, T1059.001 | False Positive (IT automation) |
| 4 | Kerberoasting Followed by Lateral Movement | T1558.003, T1021.002, T1003.001 | True Positive (Full IR) |
| 5 | DNS Tunneling to Rare External Domain | T1048.003, T1071.004 | True Positive (C2 beacon) |
Investigation #4 is a full incident response report covering the complete attack chain:
- Initial access: Valid domain credentials obtained via phishing
- Discovery: BloodHound collection via Sharphound (
T1087.002) - Credential access: Kerberoasting attack targeting service accounts (
T1558.003) - Lateral movement: PsExec to domain controller (
T1021.002) - Credential dumping: LSASS dump via procdump on DC (
T1003.001) - Containment: Account disable, session termination, network isolation
- Remediation: KRBTGT password reset (twice), service account rotation, GPO audit
- Detection improvements: New Sigma rules deployed, alert thresholds tuned, EDR block rules added
The investigations/ directory documents false positive analysis and rule refinement:
- Account Discovery (net.exe): Reduced 94 alerts/day to 3 alerts/day by filtering IT admin workstations and service accounts
- Scheduled Task Creation: Whitelisted known IT automation tasks by TaskName and Author pattern
- RDP from Public IP: Added geolocation context — only alert on non-UK countries and first-seen IPs
Log Source → Logstash/Agent → Elasticsearch → Kibana Rule → Alert → Investigation → MITRE ATT&CK Mapping → Rule Tuning → Documentation
This lab was built on a local ELK stack with the following components:
# Elastic Stack
docker-compose up -d elasticsearch kibana logstash
# Windows event collection
winlogbeat setup --dashboards
winlogbeat -e
# Deploy Sigma rules to Elastic
sigma convert -t elastalert -p ecs_windows detections/*.yml > elastic_rules.ndjsonGideon Opukeme — Cybersecurity Engineer
MSc Cyber Security, University of Aberdeen
github.com/Gideon145